In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
{
"license": "CC-BY-4.0",
"sources": [
{
"database_specific": {
"status": "Modified"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41035",
"id": "CVE-2026-41035",
"imported": "2026-07-17T22:14:48.043Z",
"modified": "2026-07-15T02:21:12.250Z",
"published": "2026-04-16T07:16:31.003Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-41035"
},
{
"html_url": "https://github.com/advisories/GHSA-m34r-4v3r-pp9v",
"id": "GHSA-m34r-4v3r-pp9v",
"imported": "2026-07-17T22:14:48.194Z",
"modified": "2026-07-10T12:31:53Z",
"published": "2026-04-16T09:31:44Z",
"url": "https://api.github.com/advisories/GHSA-m34r-4v3r-pp9v"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23215",
"id": "EUVD-2026-23215",
"imported": "2026-07-17T22:14:56.902Z",
"modified": "2026-07-10T12:05:54Z",
"published": "2026-04-16T06:53:05Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-23215"
}
]
}